ISO 13485 Internal Audit: Step-by-Step Process, Requirements & Checklist
Medical device companies operate in one of the most regulated industries in the world. Maintaining compliance is not only necessary for certification, but also for product quality, patient safety, and market access. One of the most important parts of a compliant Quality Management System (QMS) is the internal audit process under International Organization for Standardization ISO 13485.
An effective ISO 13485 internal audit helps organizations identify gaps, improve processes, prepare for certification audits, and maintain regulatory compliance across global markets.
This guide explains everything you need to know about ISO 13485 internal audits, including requirements, audit planning, audit checklists, common findings, and best practices for medical device manufacturers.
Talk to our experts
What Is an ISO 13485 Internal Audit?
An ISO 13485 internal audit is a systematic and independent evaluation of a company’s Quality Management System to determine whether processes comply with:
- ISO 13485:2016 requirements
- Internal procedures and SOPs
- Applicable regulatory requirements
- Customer and product quality requirements
The purpose of the audit is not just to “pass certification.” It is designed to improve operational effectiveness and ensure consistent medical device quality and safety.
Internal audits are mandatory under Clause 8.2.4 of ISO 13485.
Why Internal Audits Are Important in ISO 13485
Internal audits provide organizations with a proactive way to identify nonconformities before external auditors or regulatory authorities discover them.
Key Benefits of ISO 13485 Internal Audits
Helps Maintain Certification
Regular audits ensure ongoing compliance with ISO 13485 certification requirements.
Improves Product Quality
Audits help identify process weaknesses that could affect device safety or performance.
Reduces Regulatory Risk
A strong internal audit process helps companies prepare for inspections from authorities like:
- U.S. Food and Drug Administration FDA
- European Commission EU regulatory bodies
- Central Drugs Standard Control Organisation CDSCO
- Health Canada
Encourages Continuous Improvement
Audits reveal opportunities to improve efficiency, documentation, training, and risk management.
Enhances Employee Awareness
Departments become more aware of compliance responsibilities and quality objectives.
ISO 13485 Internal Audit Requirements
According to ISO 13485:2016, organizations must:
- Conduct internal audits at planned intervals
- Determine whether the QMS conforms to ISO 13485 requirements
- Verify implementation and effectiveness
- Maintain documented audit procedures
- Keep audit records and reports
- Take corrective actions for identified nonconformities
The audit program should consider:
- Importance of processes
- Previous audit results
- Risk levels
- Regulatory impact
Who Should Perform ISO 13485 Internal Audits?
Internal audits should be conducted by trained and competent auditors who are independent of the area being audited whenever possible.
Auditor Competency Requirements
Auditors should understand:
- ISO 13485 requirements
- Medical device regulations
- Risk management principles
- CAPA systems
- Documentation controls
- Manufacturing and validation processes
Many organizations either:
- Train in-house auditors, or
- Hire external ISO 13485 consultants
Schedule a Compliance Consultation
Accelerate Market Access with End-to-End Regulatory Guidance
Step-by-Step ISO 13485 Internal Audit Process
1. Develop an Audit Program
Create an annual audit schedule covering all QMS processes.
Typical audit areas include:
- Document control
- Risk management
- Design controls
- Supplier management
- Production controls
- CAPA
- Complaint handling
- Training
- Sterilization validation
- Cleanroom controls
Risk-based auditing is strongly recommended.
2. Define Audit Scope and Objectives
The audit scope should clearly mention:
- Department or process
- Applicable standards
- Regulatory requirements
- Audit duration
- Audit criteria
Example:
“Internal audit of purchasing controls and supplier evaluation processes as per ISO 13485 Clause 7.4.”
3. Prepare an Audit Checklist
An audit checklist helps ensure consistency and complete coverage.
Common ISO 13485 Audit Checklist Areas
Process Area | Key Audit Questions |
Document Control | Are SOPs approved and current? |
Training | Are competency records maintained? |
Risk Management | Is ISO 14971 integrated into processes? |
CAPA | Are corrective actions effective? |
Supplier Control | Are suppliers evaluated and monitored? |
Production | Are process validations documented? |
Complaint Handling | Are complaints investigated properly? |
Traceability | Can products be traced completely? |
4. Conduct the Audit
Auditors gather evidence through:
- Interviews
- Document reviews
- Record verification
- Process observation
- Sampling activities
The audit should focus on objective evidence rather than assumptions.
5. Record Audit Findings
Audit findings are generally categorized as:
Major Nonconformity
A serious failure affecting QMS effectiveness or product safety.
Minor Nonconformity
An isolated issue with limited impact.
Observation
An opportunity for improvement without direct noncompliance.
Common ISO 13485 Internal Audit Findings
Medical device companies often encounter findings related to:
- Incomplete training records
- Outdated SOPs
- Missing validation records
- Ineffective CAPA implementation
- Supplier qualification gaps
- Poor risk management linkage
- Inadequate complaint investigations
- Calibration record deficiencies
Addressing these issues early helps avoid regulatory action and certification delays.
Corrective Action After Internal Audits
Corrective Action and Preventive Action (CAPA) is critical after identifying nonconformities.
Effective CAPA Process
Root Cause Analysis
Identify the actual reason behind the issue.
Corrective Action Implementation
Fix the issue systematically.
Verification of Effectiveness
Ensure the action resolved the problem permanently.
Documentation
Maintain proper CAPA records and evidence.
Risk-Based Internal Auditing in ISO 13485
Risk-based auditing focuses more attention on high-risk processes such as:
- Sterilization
- Software validation
- Implantable devices
- Design controls
- Supplier quality
- Cleanroom operations
This approach improves audit effectiveness and regulatory readiness.
ISO 13485 Internal Audit Best Practices
Conduct Audits Throughout the Year
Avoid auditing everything just before certification audits.
Use Experienced Auditors
Medical device regulations require technical and regulatory understanding.
Focus on Process Effectiveness
Do not limit audits to document reviews alone.
Review Regulatory Requirements
Ensure alignment with:
Maintain Audit Evidence
Organized records simplify certification and inspection readiness.
Internal Audit vs External Audit
Internal Audit | External Audit |
Conducted by organization or consultant | Conducted by certification body |
Focuses on improvement | Focuses on certification |
Flexible scheduling | Fixed audit schedule |
Identifies gaps early | Verifies compliance status |
Both are important for maintaining an effective QMS.
How Often Should ISO 13485 Internal Audits Be Conducted?
ISO 13485 does not define a fixed frequency. However, most medical device companies conduct:
- Full QMS audits annually
- High-risk process audits quarterly or semi-annually
Audit frequency should be based on:
- Process risk
- Regulatory requirements
- Previous audit findings
- Organizational changes
ISO 13485 Internal Audit Checklist Example
Management Responsibility
- Quality policy established
- Management review conducted
- Quality objectives monitored
Design and Development
- Design inputs documented
- Verification and validation records available
- Design changes controlled
Production and Process Controls
- Process validation records maintained
- Equipment calibration completed
- Environmental controls monitored
Supplier Management
- Approved supplier list maintained
- Supplier evaluations documented
- Incoming inspection records available
Complaint Handling
- Complaints logged properly
- Investigations completed
- Regulatory reporting assessed
How Operon Strategist Supports ISO 13485 Internal Audits
Operon Strategist provides end-to-end consulting support for medical device companies seeking ISO 13485 compliance, certification readiness, and regulatory approvals.
Our ISO 13485 Services Include
- ISO 13485 implementation consulting
- Internal audit support
- Gap analysis
- CAPA management guidance
- SOP and QMS documentation
- Risk management documentation
- Supplier quality system setup
- Mock audits
- Regulatory compliance consulting
- FDA and CE Marking support
- MDSAP consulting
- Training for internal auditors
We support:
- Medical device startups
- Manufacturers
- Importers and exporters
- Contract manufacturers
- Sterile medical device facilities
Our team helps organizations build practical and inspection-ready quality systems aligned with global medical device regulations.
Ensure Seamless Regulatory Compliance for Your Device
Get Your Medical Device Market-Ready with Expert Regulatory Support
FAQ's
What is an ISO 13485 internal audit?
An ISO 13485 internal audit is a planned and documented evaluation of an organization’s quality management system to determine whether its processes conform to ISO 13485 requirements and the organization’s own QMS procedures.
What does Clause 8.2.4 of ISO 13485 require?
Clause 8.2.4 requires organizations to conduct internal audits at planned intervals using a documented audit process. The audit program should consider the status and importance of processes and previous audit results. Auditors should be appropriately selected to maintain objectivity and impartiality, and the organization must address findings and conduct appropriate follow-up.
How often should an ISO 13485 internal audit be conducted?
ISO 13485 requires internal audits at planned intervals rather than prescribing one universal frequency for every organization or process. Audit frequency should consider process importance, previous audit results, changes, and other relevant QMS factors.
What should an ISO 13485 internal audit checklist include?
An ISO 13485 internal audit checklist should be customized to the audit scope and may cover QMS documentation, management responsibility, training, design and development, purchasing, supplier controls, production, validation, traceability, nonconforming product, complaints, CAPA, internal audits, and management review.